CWE-457
205 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Use of Uninitialized Variable
The code uses a variable that has not been initialized, leading to unpredictable or unintended results.
CVEs (205)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Opensc Project Redhat2Enterprise Linux OpenscJun 30, 2026 Sep 3, 2024 N/A· v4 3.9 LOW· v3 N/A· v2 A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking...Show more |
2Opensc Project Redhat2Enterprise Linux OpenscJun 30, 2026 Sep 3, 2024 N/A· v4 3.9 LOW· v3 N/A· v2 A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs....Show more |
2Opensc Project Redhat2Enterprise Linux OpenscJun 30, 2026 Sep 3, 2024 N/A· v4 3.9 LOW· v3 N/A· v2 A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs....Show more |
2Opensc Project Redhat2Enterprise Linux OpenscJun 30, 2026 Sep 3, 2024 N/A· v4 3.9 LOW· v3 N/A· v2 A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK.
The problem is missing initialization of variables expected to be initialized (as arguments to other functions, etc.). |
In Xpdf 4.05 (and earlier), invalid header info in a DCT (JPEG) stream can lead to an uninitialized variable in the DCT decoder. The proof-of-concept PDF file causes a segfault attempting to read from an invalid address. |
oFono AT CMGR Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. An attacker must first ob...Show more |
oFono AT CMT Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. An attacker must first obt...Show more |
oFono AT CMGL Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. An attacker must first ob...Show more |
1Qualcomm 136Ar8035 Firmware Csra6620 FirmwareCsra6640 Firmware+133 moreJun 17, 2026 Aug 5, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while processing IOCTL call to set metainfo. |
Uninitialized Use in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical) |
1Autodesk 9Advance Steel AutocadAutocad Architecture+6 moreJun 17, 2026 Jun 25, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 A maliciously crafted STP file, when parsed in stp_aim_x64_vc15d.dll through Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, can lead to code execution...Show more |
1Autodesk 9Advance Steel AutocadAutocad Architecture+6 moreJun 17, 2026 Jun 25, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 A maliciously crafted MODEL file, when parsed in ASMkern229A.dllthrough Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, could lead to code execution in...Show more |
4Owletcare RokuThroughtek+1 more5Cam 2 Firmware Cam FirmwareCam V3 Firmware+2 moreJun 17, 2026 May 15, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 ThroughTek Kalay SDK uses a predictable PSK value in the DTLS session when encountering an unexpected PSK identity |
HDF5 Library through 1.14.3 may use an uninitialized value in H5A__attr_release_table in H5Aint.c. |
Foxit PDF Reader Annotation Use of Uninitialized Variable Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User inte...Show more |
Foxit PDF Reader Annotation Use of Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader....Show more |
An issue in LIEF v.0.14.1 allows a local attacker to obtain sensitive information via the name parameter of the machd_reader.c component. |
Trimble SketchUp Viewer SKP File Parsing Uninitialized Variable Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp View...Show more |
1Pdf Xchange 2Pdf Tools Pdf Xchange EditorJun 17, 2026 May 3, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 PDF-XChange Editor J2K File Parsing Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Edito...Show more |
1Pdf Xchange 2Pdf Tools Pdf Xchange EditorJun 17, 2026 May 3, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 PDF-XChange Editor U3D File Parsing Uninitialized Variable Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User i...Show more |